Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 789 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 789
Topic #: 1
[All 312-49v10 Questions]

In a scenario where a potential security incident has occurred on a cloud-based service, and an investigator is brought in to examine the system, what type of data acquisition would likely be beneficial in this situation? Also, explain the volatile data type that might be most interesting to the investigator.

  • A. Live acquisition should be employed to gather dynamic data from the system, concentrating on open files and command history
  • B. Dead acquisition should be used to collect static data from the system, focusing on slack space and swap files
  • C. Live acquisition would be advantageous to acquire volatile data, emphasizing data stored on cloud services and unencrypted containers that arc open on the system
  • D. Dead acquisition should be utilized to capture non-volatile data from the physical hard disk, focusing on unallocated drive space
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
aqeel1506
4 months ago
Why Option A is Better: Option A emphasizes gathering a comprehensive set of volatile data, including: Open Files: Crucial for understanding what data was in use at the time of the incident. Command History: Provides insight into what actions were taken by the user or attacker. Running Processes and Network Connections: Helps in identifying active threats or compromised components. Option C is somewhat narrow in its focus. While it includes important elements like data stored on cloud services and unencrypted containers, it might overlook other critical volatile data that live acquisition should cover comprehensively.
upvoted 1 times
...
ala76nl
4 months, 2 weeks ago
Selected Answer: A
Command history
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...